Android and iPhone, explained without the sales pitch
The Cricbet99 App: What You Actually Download
Search for the Cricbet99 app and you will find download buttons everywhere, most of them pointing at files nobody has checked. This page explains what the app really is, how to install an APK on Android without handing your phone to a stranger, what iPhone users get instead, and how the interface behaves once you are inside.
Member Log In
The same credentials work on the app and the browser.
This page is protected by reCAPTCHA. Our Privacy Policy and Terms of Service apply. Strictly 18+.
Start here
The honest truth about betting apps
Before you tap any download button, it helps to know what is inside the file.
Almost every betting app you can install in India, including the Cricbet99 app, is a web wrapper. That word sounds technical but the idea is simple. Someone takes the mobile website, puts it inside a thin native shell, adds an icon and a splash screen, and ships it as an APK. When you open it, what you are looking at is the same page your browser would load, running inside a window with no address bar.
I am not saying that as an insult. Wrappers are a sensible choice for a platform where odds, markets and casino tables change weekly, because the operator ships a fix on the server and every phone sees it immediately.
But it does change what the app is worth to you. A wrapper cannot make odds arrive faster, because the data still travels over the same connection. It cannot give you features the website does not already have. What it genuinely adds is convenience: a home screen icon, a session that survives you switching apps, push notifications when a market settles, and a full screen without browser chrome eating forty pixels at the top.
Why it is not on the Play Store
People assume an app missing from the Play Store must be dangerous. That is the wrong conclusion. Google's Developer Program Policy allows real-money gambling apps only in a short list of approved countries, with a licence in each one, and India is not on that list. So no exchange serving Indian users can list a real-money app there, no matter how well built it is. The absence is a policy fact, not a quality signal.
The same rule pushes every operator to distribute the file directly, and that is where the actual risk lives. When a file is handed around on WhatsApp, Telegram and random blog posts, nobody can tell you which copy you have. Somebody can take the genuine APK, decompile it, add a keylogger or an overlay that steals your login, repackage it, and send it on with the same icon and name. Two files that look identical on your screen can behave completely differently.
That is the real threat model. Not the app itself, and not the fact that Google will not host it. The threat is the chain of hands the file passed through before it reached you.
What this means for you in practice
Three things follow. First, where you get the file matters more than anything else about it. Ask your account manager directly, on the same WhatsApp thread you use for deposits, and take the link from there. A file forwarded by a friend, a link in a YouTube description, a download button on a site you have never heard of: those are all unknown-quantity sources, and no amount of scanning fully compensates.
Second, you are not missing much if you skip the app entirely. Open the site in Chrome and use it. If you want the icon without the file, Chrome's Add to Home Screen puts a launcher on your home screen that opens the site full screen and installs nothing.
Third, guard the login rather than the app. Whatever you install, what an attacker wants is your username and password, because that is what turns into money. Use a password you use nowhere else, never type it into a page you reached from a search ad, and read our Cricbet99 login guide for the full list of ways credentials leak.
The app is a convenience layer over the website, it is absent from the Play Store because of Google's policy rather than because of anything sinister, and the only part of the process that genuinely puts you at risk is where the file came from. Get it from the person who issued your ID, or use the browser and lose nothing.
Android
Installing the APK safely, step by step
Seven stages, from asking for the file to the first successful login.
Ask your account manager for the link
Open the same WhatsApp thread you use for deposits and ask for the current app link. You want a link, not a forwarded file, because a link points at whatever the operator is serving right now while a forwarded file could be any age and any origin. If you do not have an ID yet, request one first and the app link comes with it.
Check the domain before you tap
Read the whole link. The domain should match the site you already log into, not a shortener you cannot see through and not a lookalike with an extra letter or a hyphen. If the link goes through a URL shortener, ask for the direct one. Anyone genuine will send it without arguing.
Download the file and note its size
A wrapper build for an exchange is small, usually somewhere between 8 MB and 25 MB. If the download is 90 MB, something extra is bundled inside it and you should stop. Let the download finish completely before you touch it, because a partial APK will fail to parse and people often retry from a worse source out of frustration.
Allow installs from this one source
Android will block the install and offer you a settings shortcut. On Android 8 and newer the permission is per-app: Settings, Apps, Special access, Install unknown apps, then pick Chrome or whichever browser downloaded the file and turn it on. Grant it to that one app only. There is no longer a single global unknown-sources switch, and that change was a good one.
Let Play Protect scan it
When you tap install, Google Play Protect offers to scan the file. Say yes. It is not a complete defence, since a clean scan only means nothing known-bad was found, but it catches repackaged builds carrying common malware families and it costs you six seconds. If Play Protect refuses the install outright, delete the file and go back to your manager.
Install, then check the permission list
Tap install and wait. Once it finishes, do not open it yet. Go to Settings, Apps, find the app, and read its permissions. A wrapper needs almost nothing: internet, storage for screenshots, and notifications. If it is holding SMS, contacts, call logs or accessibility access, uninstall it immediately. That combination is how one-time passwords get read off your phone.
Log in and turn off the settings switch
Open the app, log in with the credentials your manager issued, and confirm your balance and statement look right. Then go back to Install unknown apps and switch the permission off for your browser. It takes ten seconds and it means a stray tap on a bad link next month cannot silently install anything.
A genuine build will not ask you to disable Play Protect entirely before installing, and it will not ask for accessibility permissions. Accessibility service access lets an app read everything on your screen and tap things on your behalf, which is precisely what a credential thief needs. Any install guide telling you to grant it is either careless or lying, and either way you should close the page.
One more habit worth building. After the first login, check the statement page and confirm every entry matches what you expect. If anything looks unfamiliar, change your password from inside the app and message your manager before placing a single bet. Our guide to how a Cricbet99 ID works covers what the statement should contain.
iPhone
The iOS reality: no listing, and no APK either
What iPhone users actually get, and the two or three things they give up.
Let me be blunt, because a lot of pages are not. There is no Cricbet99 app on the Indian App Store. There will not be one. Apple applies the same licensing rule Google does, and it goes further by refusing to allow app installs from outside the App Store at all in India. On Android you can sideload an APK. On a standard iPhone you simply cannot, and no guide promising you an IPA file is describing something safe or legal.
So when a site offers an iPhone download button for a betting exchange, one of three things is happening. It is a web page dressed up as a download. It is an enterprise certificate install, which Apple revokes constantly and which is a real security risk. Or it is a scam collecting your Apple ID.
What you use instead
Safari plus Add to Home Screen. It sounds like a consolation prize and it very nearly is not. Open the exchange in Safari, log in once, then tap the Share button in the bottom bar, scroll to Add to Home Screen, name the shortcut something forgettable, and tap Add. You now have an icon on your home screen that opens the site full screen with no address bar and no Safari tabs visible. Visually it is close to indistinguishable from a native app.
Use Safari for this rather than Chrome on iOS. Chrome on iPhone can create home screen shortcuts too, but they behave less consistently and are more likely to open in a normal browser tab with the URL on display, which defeats half the point.
What you genuinely lose
Three things, and it is worth being honest about each. Push notifications are the biggest: a home screen web app on iOS can send them in recent versions, but exchange sites rarely implement the required setup, so in practice you will not get an alert when a market settles or a bet matches. You will need to check manually.
Session persistence is the second. iOS is aggressive about clearing website data, so a home screen shortcut logs you out more often than an Android app would. Expect to type your password more frequently. Annoying, but arguably safer.
Third, backgrounding. Switch to WhatsApp mid-over and come back, and the shortcut may reload the page rather than resuming where you were. On a slow connection that reload can take five or six seconds, which feels like an eternity when a price is moving. Get into the habit of not leaving the app while you have an unmatched bet sitting on screen.
Not much, honestly. The exchange interface is a web app on both platforms, so you are running the same code either way. Android users get a slightly smoother container and working notifications. iPhone users get a marginally clumsier one and, as a side effect, they never have to worry about installing a repackaged build, because there is nothing to install. That is not a bad trade.
If you are still deciding whether the whole thing is for you, the sensible route on either platform is a practice account first. Ask for a free demo ID, add the site to your home screen, and spend an evening tapping around a live match without money involved.
Inside the app
A tour of the interface
What every panel does, and which numbers actually matter.
Live prices, and why they flicker
The first thing you notice is movement. Prices on an exchange update continuously, and the app flashes a cell briefly when a number changes. During a quiet middle over that flicker is gentle. In the last two overs of a chase it is constant, and the screen can look like it is arguing with itself.
Each selection shows two figures side by side. The blue one on the left is the back price, the pink one on the right is the lay price, and the small number underneath each is the amount currently available to match at that price. That second number is the one nobody reads and everybody should. A gorgeous back price with ₹800 available behind it will only fill ₹800 of your ₹5,000 stake. The rest sits unmatched until someone takes it, which may be never.
One-tap back and lay
Tapping a blue cell opens the slip with a back bet loaded at that price. Tapping pink loads a lay. The tap targets on a phone are small and sit next to each other, which is exactly the design flaw you would expect to cause problems, and it does. Backing when you meant to lay is the single most common mobile mistake I hear about.
One habit fixes it. Read the slip header before typing a stake, because it says BACK or LAY in plain text. It takes under a second and it will save you a painful mistake at some point.
The bet slip
The slip slides up from the bottom and holds the selection name, the price, a stake field and a row of quick-stake buttons. Those quick buttons are usually set to values like 100, 500, 1000 and 5000, and most apps let you customise them in settings. Do that on day one. Default presets that do not match your normal stake size are how people accidentally fire in ten times what they intended.
Below the stake you get the profit figure for a back bet or the liability figure for a lay. On a lay, that liability is your real risk, and it is bigger than the number you typed. Lay at 5.0 for ₹1,000 and you are risking ₹4,000 to win ₹1,000. The app tells you this before you confirm. Read it every single time.
The exposure display
Somewhere near your balance sits a second, usually red, figure. That is your exposure: money committed to bets that have not settled. It is not available to stake and it is not available to withdraw. New users regularly panic that money has gone missing when the balance drops, when in fact it has simply moved into that column.
Open the market view and you can see exposure broken down per outcome, which shows you what you win or lose in each scenario. That per-outcome view is the most useful screen in the whole app and the least used. If you check one thing before confirming a bet, make it this.
The casino lobby
There is a tab for live casino tables: roulette, Andar Bahar, Teen Patti, Dragon Tiger, and a wall of slot-style games. It runs around the clock, the rounds last about thirty seconds, and it is the easiest place on the platform to undo a good week of cricket trading. I would set a separate budget for it or ignore the tab entirely. Nothing you learn about reading a cricket market helps you there.
Wallet and statement
The wallet section shows your balance and the deposit and withdrawal request forms, which under the agent model mostly hand you back to WhatsApp. The statement is the important one: every deposit, bet, settlement, commission charge and withdrawal, in order, with running balances. Check it weekly. It is your only independent record of what happened, and if you ever need to query something with your manager, a timestamp from the statement ends the argument in one message.
Performance
Budget phones, patchy 4G and what it costs you
How the app behaves when the hardware and the network are not ideal.
An exchange app is not heavy in the way a game is. There are no 3D assets and no video streams. What it does instead is receive a steady drip of small price updates and redraw parts of the screen constantly, which is a different kind of load and one that budget hardware handles less gracefully than you might expect.
On a phone with 3 GB of RAM the app itself is fine. The problem is everything else. Android keeps background apps alive until memory runs short, then starts killing things, and a web wrapper is an easy target. You come back from a phone call and it reloads from scratch. Nothing is lost, since your bets live on the server, but you lose eight seconds and your place in a moving market.
Data use, measured honestly
The price feed is text, so it is smaller than people assume. Watching a single cricket match end to end, actively, uses somewhere in the region of 40 to 90 MB. A casual half hour is more like 10 MB. Those are rough figures from my own usage rather than a published spec, and they vary with how many markets you have open, but the order of magnitude holds.
The exception is live streaming. If the app carries an embedded match video, that alone will use 300 MB to 1 GB an hour depending on quality, which dwarfs everything else combined. If you are on a 1.5 GB daily pack, the stream is what empties it, not the odds.
| Activity | Rough data use | Notes |
|---|---|---|
| Checking balance and statement | Under 2 MB | Negligible on any pack. |
| Watching one market for 30 minutes | 8 to 15 MB | Depends on how fast prices move. |
| Full T20 match, actively trading | 40 to 90 MB | More if you keep several markets open. |
| Casino tables, one hour | 60 to 150 MB | Live dealer video is the bulk of it. |
| Embedded match stream, one hour | 300 MB to 1 GB | By far the biggest consumer. |
Settings worth changing on day one
Turn the in-app stream off unless you are actually watching it. Most people have the match on a television or another device anyway, and the stream is usually five to twenty seconds behind the live feed, which makes it actively misleading for trading.
Close markets you are not using. Every open market is another subscription pulling updates, and on a weak phone that shows up as stutter. Two or three markets at a time is comfortable. Ten is not.
Exempt the app from battery optimisation if your phone keeps killing it: Settings, Apps, the app, Battery, then Unrestricted. This matters most on Xiaomi, Realme, Vivo and Oppo devices, whose memory management will otherwise close a backgrounded app within a minute.
When the network is the problem
Patchy 4G produces a specific and dangerous failure. Your connection drops for four seconds, the app keeps showing the last price it received, and you tap a stale number. When the connection returns, either the bet fails or it matches at a price you did not intend. Most apps show a reconnecting indicator somewhere near the top. Learn where it is on your build and treat it as a stop sign.
My rule on a weak signal is simple: do not chase in-play prices. Place your position before the over starts, or wait. Trading a fast market through an unstable connection is how you end up matched at a terrible price and blaming the platform for something the network did. If your line is regularly unstable, read the pieces on our blog about pre-match positioning, which suits it far better.
Warning signs
Nine red flags on a fake or repackaged build
Any one of these is enough to uninstall. Do not wait for a second.
It asks you to disable Play Protect
No legitimate build needs Google's scanner switched off. That instruction exists for exactly one reason, which is that the file fails the scan. Delete it.
It wants SMS or call log access
A betting app has no business reading your messages. That permission is how one-time passwords for your bank get intercepted, and there is no innocent version of it.
The file is far too large
A wrapper is 8 to 25 MB. A 100 MB APK for the same interface means something extra is riding along, and whatever it is was not advertised on the download page.
The login screen looks slightly off
Wrong shade of green, a squashed logo, a font that does not match the website, a typo in the placeholder text. Repackagers rebuild the login screen to capture credentials and they rarely get it pixel perfect.
It requests accessibility access
This is the worst one on the list. Accessibility service permission lets an app read your entire screen and tap on your behalf. Nothing about showing cricket odds requires it.
Ads appear inside the app
Third-party banner ads inside a betting exchange are not a business model, they are a symptom. Someone has bolted an ad SDK onto the wrapper, which means they had the file open and modified it.
The name in your app drawer is wrong
Check the installed app's name and package details in Settings. A name that differs from what the download page promised, or a generic label like WebApp, means the shell is somebody else's.
It promises guaranteed wins or free money
A download page advertising a hack, a prediction feature or free credit on install is not distributing the real app. That copy is bait, and what it is fishing for is your login.
Your battery and data spike overnight
Check Settings, Battery and Data usage a day after installing. An app that is busy while you sleep is talking to something, and it is not the odds feed.
If you have already installed something that matches any of these, do three things in order. Uninstall the app. Change your exchange password from a browser on a different device. Then message your account manager and tell them what happened, because they can watch the account for unusual activity while you sort your phone out. If your banking apps sit on the same phone, change those passwords too and check recent transactions.
Permissions
Every permission, and whether it should worry you
Read this list once and you will never have to guess at an install prompt again.
| Permission | Legitimate use in a betting app | Verdict |
|---|---|---|
| Internet / network state | Loading the interface and receiving price updates. Also lets the app show a reconnecting warning when the signal drops. | Expected |
| Storage (photos and media) | Saving screenshots of bets and statements, and picking a payment screenshot to send to support. | Expected |
| Notifications | Alerting you when a bet matches, a market settles, or a withdrawal is processed. | Expected |
| Vibrate | Haptic feedback when a bet is confirmed. Cosmetic and harmless. | Expected |
| Camera | Scanning a UPI QR code or uploading a document if verification is ever requested. Reasonable, but it should be requested at the moment you use it, not at install. | Ask why |
| Approximate location | Some operators check which state you are in, since several Indian states restrict access. A defensible reason, though many apps ask and never explain it. | Ask why |
| Precise location | There is no market, odds feature or payment flow that needs your exact position. Approximate would do everything precise does here. | Refuse |
| Contacts | Usually justified as a refer-a-friend feature. Your contact list is valuable data and referral links work perfectly well without it. | Refuse |
| SMS (read or receive) | None. Android has an autofill API for one-time passwords that reads a single matching message without granting full inbox access. | Uninstall |
| Call log / phone state | None whatsoever. This is device fingerprinting at best and interception at worst. | Uninstall |
| Accessibility service | None. This grants the ability to read your screen and act on it. Malware asks for it. Legitimate betting apps do not. | Uninstall |
| Draw over other apps | Occasionally used for a floating odds widget, but it is also how overlay attacks paint a fake login on top of a real one. | Refuse |
| Install unknown apps | An app that wants permission to install other apps is a dropper. There is no acceptable version of this request. | Uninstall |
| Device admin | Grants control over your lock screen and the ability to wipe the device. It also makes the app much harder to remove. | Uninstall |
How to actually check
Android hides this less than people think. Settings, Apps, pick the app, then Permissions shows what is granted and Unused apps shows what it asked for. Some skins also list a separate Special access section, which is where accessibility, display over other apps and install permissions live. Those three are the ones worth checking properly, because they never appear as ordinary runtime prompts.
Revoking is safe. Turn off a permission the app genuinely needs and it will simply ask again when it hits the feature, with context this time. Start restrictive and loosen only when something breaks.
Individually, a few of these are merely questionable. In combination they are a signature. SMS plus accessibility plus draw over other apps is the standard toolkit for stealing a login and then approving the transaction it enables. If you see two of those three on any app, on your phone, from any source, remove it and change the passwords for anything financial on that device.
Maintenance
Updating without losing your session
Sideloaded apps do not update themselves, and version drift causes strange bugs.
Here is something the Play Store normally handles for you and now does not. A sideloaded app has no update channel. Nobody pushes a new version to your phone overnight. Whatever build you installed in March is still the build you are running in November unless you go and get a new one yourself.
Most of the time this is invisible, because the interface lives on the server and the shell barely matters. Then the operator changes something structural, the old shell handles it badly, and you get a bug that makes no sense: a bet slip that will not close, a casino table loading to a blank screen, a statement stuck on the spinner. You restart the phone and assume the platform is broken. It usually is not. Your container is just old.
The safe way to update
Install the new APK over the top of the existing one rather than uninstalling first. Android treats it as an in-place upgrade, the app's stored data survives, and your session normally survives with it. If you uninstall first, everything local goes: saved login, stake presets, layout settings, notification preferences. You will be typing your password again and rebuilding your quick-stake buttons for no reason.
One condition applies. The new file has to be signed with the same key as the old one, which it will be if it came from the same source. If Android refuses the install with a message about a conflicting package or an incompatible signature, stop. That is Android telling you the new file was built by someone other than whoever built the one you have. Do not uninstall the working app to force the new one through. Go back to your account manager and ask.
Before you tap update
Two small things. Make sure you have no unsettled bets in flight, because although your positions live safely on the server, an in-place upgrade closes the app instantly and you do not want that happening with an unmatched bet you were about to cancel. And write your username down somewhere outside the phone. If the session does get cleared and autofill has quietly forgotten your credentials, a saved password in the app is no help at all.
When to bother updating
Not constantly. My rule of thumb is three triggers. Something breaks that also works in the browser on the same phone, which is the clearest signal that the shell is the problem. Your manager tells you a new build is out, which they generally do before a big tournament. Or the app has been on your phone for six months, which is long enough for drift to accumulate whether or not you have noticed symptoms.
Outside those, leave it alone. Every install is a moment where a wrong file can slip in, so there is no benefit in updating for its own sake.
When something misbehaves, open the same site in Chrome on the same phone and try the same action. Works in the browser but not the app? Your build is stale, get the current one. Broken in both? The platform is having a problem and updating will change nothing, so message support instead. This one test saves an enormous amount of pointless reinstalling.
None of this applies on iPhone, incidentally. A home screen shortcut is a bookmark, so it always loads whatever the server is serving and can never be out of date. That is one genuine advantage of the iOS route. If you are still setting up, our registration guide covers getting the credentials, and the homepage explains how exchange pricing works. Whatever you install, keep it 18 plus and read our responsible gaming notes: an app on your home screen makes betting available every minute of the day, and that convenience cuts both ways.
Questions
Frequently asked questions
Is the Cricbet99 app on the Google Play Store?
No, and it will not be. Google only permits real-money gambling apps in a short list of licensed countries, and India is not one of them. Every exchange serving Indian users therefore distributes its Android file directly. The absence from the Play Store is a policy rule, not evidence that the app is unsafe.
How do I download the Cricbet99 APK safely?
Ask your account manager for the link on the same WhatsApp thread you use for deposits, and take it from there rather than from a search result, a forwarded file or a YouTube description. Check the domain matches the site you log into, let Play Protect scan the file, and read the app's permissions before you open it.
Is there an iPhone version of the app?
There is no App Store listing and no IPA you can safely install, because Apple blocks both the listing and outside installs in India. Use Safari instead, log in, then tap Share and Add to Home Screen. You get a full-screen icon that behaves like an app. Anyone offering you an iPhone download file is selling you a risk.
How much storage and data does the app use?
The install itself is small, usually between 8 MB and 25 MB. Actively trading a full T20 match uses roughly 40 to 90 MB of data. The one thing that changes the picture is an embedded live stream, which can burn 300 MB to 1 GB an hour on its own. Turn the stream off and the app is light.
Which permissions should I refuse?
Refuse contacts, precise location and draw over other apps. Uninstall immediately if the app asks for SMS, call logs, accessibility service, device admin or permission to install other apps. Internet, storage, notifications and vibrate are the only ones a betting wrapper genuinely needs.
Will I lose my session if I update the app?
Not if you install the new APK over the existing one. Android treats that as an in-place upgrade and your stored data, including the saved session and your stake presets, normally survives. Uninstalling first wipes all of it, so only do that if the installer refuses the upgrade.
Why does the app work on my friend's phone but not mine?
Usually version drift. Sideloaded apps do not update themselves, so two people can be running builds months apart. Test the same action in Chrome on your own phone: if it works in the browser but not the app, your build is stale and you need the current one from your manager.
Do I actually need the app at all?
No. The interface is the same web app either way, so the browser gives you identical markets, prices and features. The app adds a home screen icon, better session persistence and working notifications. If those are not worth the install to you, use Chrome and add the site to your home screen instead.
Can I stay logged in on the app and my laptop at the same time?
Generally not. One live session per ID is the normal rule, so logging in on a laptop tends to push the phone session out. That is a security feature rather than a fault, and it is also why an unexpected logout is worth investigating rather than ignoring.
What should I do if I installed a fake build?
Uninstall it, then change your exchange password from a browser on a different device, then tell your account manager so they can watch the account. If your banking apps live on the same phone, change those passwords as well and check recent transactions. Move fast, because credential theft is quiet by design.
Want the verified app link?
Ask on WhatsApp and you get the current build plus your login, usually inside two minutes. Start small, run one withdrawal, then decide.
18+ only. Betting involves financial risk and can be addictive. Please play responsibly.